CVE-2018-20001: Libav

Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.

In Libav 12.3, there is a floating point exception in the range_decode_culshift function (called from range_decode_bits) in libavcodec/apedec.c that will lead to remote denial of service via crafted input.

Affected products

  • Libav Libav: version 12.3 only

Published 2018-12-10. Last modified 2026-06-17.